Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleicritical
VMware vCenter Server - Out-of-Bounds Write
CVE-2023-34048CRITICALsob ataque
VMware vCenter Server Out-of-Bounds Write Vulnerability
95RISCO
abrir
Nucleihigh
Vite Dev Server - Information Exposure
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
36RISCO
abrir
Nucleihigh
SRS - Command Injection
SRS has command injection vulnerability in demonstration api-server for HTTP callback.
36RISCO
abrir
Nucleicritical
SonicWall GMS and Analytics Web Services - Shell Injection
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RISCO
abrir
Nucleihigh
SonicWall GMS and Analytics - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RISCO
abrir
Nucleicritical
Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting
CVE-2023-34192CRITICALsob ataque
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co
95RISCO
abrir
Nucleimedium
Kyocera TASKalfa printer - Path Traversal
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read ar
40RISCO
abrir
Nucleicritical
MOVEit Transfer - Remote Code Execution
CVE-2023-34362CRITICALsob ataqueransomware
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
Nucleicritical
WordPress Canto Plugin <= 3.0.4 - File Inclusion
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RISCO
abrir
Nucleimedium
Hoteldruid 3.0.5 - Cross-Site Scripting
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected web
18RISCO
abrir
Nucleicritical
Gibbon v25.0.0 - Local File Inclusion
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files
50RISCO
abrir
Nucleimedium
Gibbon v25.0.0 - Cross-Site Scripting
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to ex
18RISCO
abrir
Nucleicritical
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
Nucleicritical
JeecgBoot 3.5.0 - SQL Injection
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interfac
23RISCO
abrir
Nucleicritical
bloofoxCMS v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=u
43RISCO
abrir
Nucleicritical
bloofoxCMS v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=s
43RISCO
abrir
Nucleicritical
bloofoxCMS v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=s
43RISCO
abrir
Nucleicritical
Bloofox v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=s
43RISCO
abrir
Nucleicritical
bloofoxCMS v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mod
43RISCO
abrir
Nucleicritical
Bloofox v0.5.2.1 - SQL Injection
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=s
43RISCO
abrir
Nucleimedium
Hestiacp <= 1.7.7 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
28RISCO
abrir
Nucleihigh
Traggo Server - Local File Inclusion
Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
18RISCO
abrir
Nucleicritical
Chamilo Command Injection
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir
Nucleicritical
FortiWLM - Directory Traversal
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to ex
48RISCO
abrir
Nucleicritical
Fortinet FortiWLM Unauthenticated Command Injection Vulnerability
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
48RISCO
abrir
Nucleicritical
Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass
CVE-2023-35078CRITICALsob ataqueransomware
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
Nucleicritical
MobileIron Core - Remote Unauthenticated API Access
CVE-2023-35082CRITICALsob ataqueransomware
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir
Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email
36RISCO
abrir
Nucleimedium
XWiki >= 6.0-rc-1 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
43RISCO
abrir
Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
43RISCO
abrir
anteriorpágina 129 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.